Bitcoin's Quantum Conundrum: A Race Against Time to Safeguard 6.9 Million Coins

Not all aspects of bitcoin are vulnerable to quantum computer attacks. The process of bitcoin mining, which involves adding new blocks to the blockchain, utilizes a type of mathematics known as hashing that quantum computers are unable to effectively breach. As a result, the blockchain itself and the rule that new bitcoins can only be created through mining would remain intact in the event of a quantum attack. The production of blocks and the continuity of the chain would not be disrupted. However, ownership would be severely compromised. Bitcoin wallets rely on a different type of mathematical function that converts a private key into a public address that can be seen by anyone. This mathematical function operates effortlessly in one direction but is extremely challenging to reverse, which is the primary obstacle preventing unauthorized individuals from spending someone else's coins. The first part of this series on quantum computing delved into the realm of physics, explaining that a quantum computer is fundamentally distinct from a conventional computer. It begins with an extremely cold, tiny metal loop where particles exhibit behaviors that are not observed anywhere else on Earth. The second part examined the implications of directing this machine at bitcoin. Bitcoin wallets depend on a one-way mathematical problem. Converting a private key into a public address takes mere milliseconds. However, reversing this process, from a public address back to a private key, would take a conventional computer longer than the age of the universe. A quantum algorithm known as Shor's algorithm significantly reduces this gap. A recent paper by Google demonstrated that this attack can be executed with far fewer resources than previously estimated, and within a time frame that competes with bitcoin's block times. This final piece in the series focuses on the response to this threat. It discusses what is actually at risk, the measures bitcoin has taken so far, and whether a network designed to resist coordinated change can implement the most significant security upgrade in its history before the advent of quantum hardware. The pool of vulnerable bitcoin is substantial, comprising roughly 6.9 million coins, which is approximately one-third of all the bitcoin that has been mined. The majority of this bitcoin is from the network's early years and is stored in an address format that, by default, publishes the public key. It also includes any wallet that has been spent from, as spending reveals the key for any remaining balance. A quantum attacker would not need to compete with an ongoing transaction. Instead, they could systematically work through wallets with exposed keys at their own pace. This includes the approximately 1 million bitcoin held by Satoshi Nakamoto, bitcoin's pseudonymous creator, which has remained untouched since the network's early days and is now classified as exposed. The 2021 Taproot upgrade inadvertently expanded the problem. Taproot is a modification to how bitcoin addresses function, intended to make transactions more efficient and private. A side effect of Taproot is that any bitcoin spent since its activation has published the key protecting the remaining balance at that address. Although this was not an error, it was a reasonable trade-off at the time, given the perceived longer timelines for quantum threats. Currently, there are efforts underway to address the quantum threat, but nothing concrete has emerged from Bitcoin developers yet. In contrast, Ethereum, which is often considered one of Bitcoin's largest competitors among institutional investors, has had a formal quantum-resistant program in place since 2018. The Ethereum Foundation supports four full-time teams working on the migration, along with more than ten independent developer groups that release weekly test networks. Ethereum's plan involves specific upgrades across four upcoming network-wide changes, aiming to transition Ethereum's security to new mathematics that quantum computers cannot breach. Bitcoin, on the other hand, lacks a comparable strategy. There are, however, formal proposals from developers and researchers, such as BIP-360, which would introduce new quantum-safe address types that holders could voluntarily migrate to. Another proposal from BitMEX Research suggests implementing a detection system that would trigger defensive actions if a quantum attack is observed on the network. Neither proposal has garnered broad support from bitcoin's core developers, and they address different aspects of the problem. The challenge in implementing effective solutions against the quantum threat is significant. Bitcoin's migration is more complicated than Ethereum's due to reasons unrelated to the mathematical aspects. Ethereum has a foundation that funds engineering work and a governance process that regularly passes major upgrades. Bitcoin, with its development culture that treats any central authority as a failure mode and its social consensus requiring changes to the protocol to be rare and difficult, faces a structurally harder problem. Migrating the 6.9 million exposed coins requires decisions that the network has spent twenty years avoiding. The question of whether old address formats should be frozen after a certain date to protect coins from future theft, or whether exposed coins should be allowed to move to new quantum-safe addresses using their original keys, remains unanswered. The fate of coins whose owners cannot or will not migrate also poses a significant challenge. Satoshi's coins serve as the most striking example, as freezing old formats would protect the coins from theft but render them permanently inaccessible, including to Satoshi. Leaving the old formats open means those coins remain a potential prize for whoever first develops a working quantum computer or gains access to one with the intention of attacking. Setting a migration deadline would force Satoshi to either move the coins, thereby revealing their ownership, or lose them. Every option would alter bitcoin's character in ways the network has historically been reluctant to change. The Google paper's framing serves as a summary of the industry's current stance. A successful attack on the mathematics used by bitcoin should not be seen as a wake-up call to adopt post-quantum cryptography but rather as a potential signal that the adoption of post-quantum cryptography has already failed. This implies that by the time the threat becomes apparent, the window to respond may have already closed. Developers are now faced with the question of whether a network built to resist coordinated change can coordinate the most significant security upgrade in its history before quantum hardware catches up with theoretical capabilities. Ethereum's eight-year head start suggests that starting now is the correct approach. Bitcoin's governance culture, however, suggests that the likely response will be to wait until the threat is demonstrated, and then act. Only one of these approaches will be effective if the timeline proves to be shorter than optimists estimate.